Skip to content

Follow-up #938: make corrupt-file aside helper genuinely non-throwing #1692

Description

@fluck-boss

Follow-up from the clean merge review of #938 at head 8c4ff8c (Claude note N3: #938 (comment)).

File.renameAsideCorrupt() promises best-effort failure via false, but toPath() / resolveSibling(...).toPath() may throw InvalidPathException, and Files.move / Files.setPosixFilePermissions may throw SecurityException. restrictToOwner() catches IO and unsupported POSIX modes, not SecurityException. The three settings managers call this from init-reachable recovery paths, so an escape can poison an object initializer rather than leave the manager on defaults.

Handle IllegalArgumentException and SecurityException inside the helper and its permissions subroutine. Add focused failure tests for the reachable cases while keeping the existing IO/collision behavior. Non-blocking for #938; edge-case reachability is thin.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions